Processing Agreement in the GDPR (AVG)
Personal data may not be processed just like that. Companies and organizations that want to process personal data must comply with the GDPR (AVG) (and the U-AVG). The GDPR regulates that controlling always remains obligatory for the processing of personal data.
According to the GDPR, it, therefore, does not matter whether the controller processes the personal data itself or whether it outsources this to another party – a processor. However, this final responsibility does not affect the fact that the processor also has responsibilities under the GDPR. The parties must arrange responsibility for the careful processing of personal data in a processor agreement. If the parties fail to do so, they will both be in violation of the GDPR.
